The 2015 infamous Java unserialize vulnerability

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|

The 2015 infamous Java unserialize vulnerability

Jacques Le Roux
Administrator
Hi,

I thought I warned all our users to take care about "The 2015 infamous Java unserialize vulnerability" as I called it when I created
https://cwiki.apache.org/confluence/display/OFBIZ/Keeping+OFBiz+secure 2 months ago.
But it only reached the dev ML so this mail to warn you about this vulnerability we have still in OFBiz.

We have it because of the Groovy version we use https://issues.apache.org/jira/browse/OFBIZ-6568. And you are also vulnerable if you use RMI or/and JMX
You can protect your OFBiz instance/s by following the "Be safe!" warning in the wiki page above. We use that in the demos for 2 months.

Be safe!

Jacques
Reply | Threaded
Open this post in threaded view
|

Re: The 2015 infamous Java unserialize vulnerability

Nicolas Malin-2
Thanks Jacques for all this works !

Le 05/02/2016 19:11, Jacques Le Roux a écrit :

> Hi,
>
> I thought I warned all our users to take care about "The 2015 infamous
> Java unserialize vulnerability" as I called it when I created
> https://cwiki.apache.org/confluence/display/OFBIZ/Keeping+OFBiz+secure 
> 2 months ago.
> But it only reached the dev ML so this mail to warn you about this
> vulnerability we have still in OFBiz.
>
> We have it because of the Groovy version we use
> https://issues.apache.org/jira/browse/OFBIZ-6568. And you are also
> vulnerable if you use RMI or/and JMX
> You can protect your OFBiz instance/s by following the "Be safe!"
> warning in the wiki page above. We use that in the demos for 2 months.
>
> Be safe!
>
> Jacques
Reply | Threaded
Open this post in threaded view
|

Re: The 2015 infamous Java unserialize vulnerability

Hans Bakker
In reply to this post by Jacques Le Roux
Thank you for the reminder Jacques!

On 06/02/16 01:11, Jacques Le Roux wrote:

> Hi,
>
> I thought I warned all our users to take care about "The 2015 infamous
> Java unserialize vulnerability" as I called it when I created
> https://cwiki.apache.org/confluence/display/OFBIZ/Keeping+OFBiz+secure 
> 2 months ago.
> But it only reached the dev ML so this mail to warn you about this
> vulnerability we have still in OFBiz.
>
> We have it because of the Groovy version we use
> https://issues.apache.org/jira/browse/OFBIZ-6568. And you are also
> vulnerable if you use RMI or/and JMX
> You can protect your OFBiz instance/s by following the "Be safe!"
> warning in the wiki page above. We use that in the demos for 2 months.
>
> Be safe!
>
> Jacques


--

Regards,

Hans Bakker
CEO, http://antwebsystems.com